State of Identity Attack Path Management | SO-CON 26

State of Identity Attack Path Management | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 44:29

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This talk introduces Attack Path Management (APM) as a critical discipline for scaling security operations, moving beyond traditional perimeter defense to address the complexity of modern identity-based attacks 0:47.

Key Takeaways:
• Attack Path Management is defined as the continuous process of identifying, prioritizing, and remediating risks along potential attack paths, rather than just fixing isolated vulnerabilities 0:52.
• Traditional security tools often fail at scale because they cannot effectively map the complex relationships between users, groups, and resources that attackers exploit 1:05.
• The goal is to provide actionable intelligence to teams, ensuring that remediation efforts actually reduce risk rather than just generating noise or frustration 1:15.

Effective APM requires a shift in mindset from reactive patching to proactive path analysis, enabling organizations to mitigate high-impact risks efficiently.

Sources:

  • 0:47 Introduction to the topic and speaker context.
  • 0:52 Definition of Attack Path Management.
  • 1:05 Limitations of traditional security tools.
  • 1:15 The objective of actionable remediation.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

This is the first talk of the practice track. So this is all about how can you use Blood Hound or Blood Hound Enterprise internally to um kind of um attack attack paths at scale. Uh do that without frustrating your teams or yourself um and hopefully actually fix things rather than just show a bunch of nasty things and say the world's falling. >> Um my name is Justin Coler by the way. I'm the chief product officer. Uh Jared leads our research team is the CTO and we'll get started when Jared makes his way over. >> Sorry. >> No, you're good. >> So, like I said, um this talk is uh Do you mind if we get Can we get that? >> Oh, okay. Sweet. Sweet. Thank you. Um so, we're going to talk a little bit about um attack path management in general for those that may be new. Um, who uses Blood Hound inte…